Aayat AI
Guide · Coding

Check a package for vulnerabilities and malware before you install it

Coding assistants happily install whatever package name sounds right, including typosquats, abandoned projects and versions with known holes. Check first: one package for $0.005, or a whole lockfile in one call.

Add it to Claude or Cursor free (30 seconds) See a live answer first

What to check before installing a package

  • Known vulnerabilities in the exact version, with severity and the version that fixes them (from OSV.dev, which includes GitHub's advisory database).
  • Malware: packages reported as malicious, often published under a name one letter away from a popular one.
  • Typosquats: names that look like a popular package (expres, reqeusts).
  • Deprecation and activity: whether the package is deprecated, when it was last released, and how many people use it.
  • Install scripts and licence: code that runs on install, and a licence your project can use.

How to check, from one package to a whole project

Package check ($0.005): one npm, PyPI, crates or Go package, with an ok / caution / avoid verdict, a 0-100 score and every reason.

Package audit ($0.02): up to 200 exact versions in one call. Lockfile audit ($0.05): package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, Cargo.lock, go.sum and more, up to 1,000 versions.

CVE lookup ($0.003): any CVE or GHSA id with its severity, exploit probability (EPSS) and whether CISA lists it as exploited in the wild. Using GitHub Actions? The Action check ($0.005) looks for compromised actions and unpinned versions.

  1. Add it to your coding assistant. Get a free key on the set-up page: one click in Cursor, one command in Claude Code.
  2. Ask before installing. "Check express 4.21.2 for vulnerabilities before you add it." Or tell your assistant to always check new dependencies first.
  3. Audit the lockfile. "Audit my package-lock.json and list what to upgrade."

From code or CI

Every check is a plain HTTP endpoint, so a CI step can call it. Pay per call with x402 or use an API key with prepaid credits.

curl -i "https://aayatai.com/package/check?ecosystem=npm&name=express&version=4.21.2"

Live example

Live check of express 4.21.2 on npm

Free, no sign-up: a real answer from our own health check for this input. Your own questions cost $0.005 a call, and the first 20 a day are free in Claude or Cursor.

https://aayatai.com/package/check?ecosystem=npm&name=express&version=4.21.2

Ask your AI assistant

Once it's added, just ask in plain words. For example:

Before you install it, check express 4.21.2 on npm for vulnerabilities and malware.

Get a free key and add it All tools and prices

Tools on this page

5 of these 6 are in the free trial (20 calls a day over MCP). Prices come straight from our live price list; failed calls are never charged.

ToolWhat it answersPrice per call
Package checkShould a coding agent install this package?$0.005free to try
Package auditAudit a whole dependency list in one call: up to 200 exact npm, PyPI, crates or Go package versions checked against OSV.dev for known vulnerabilities and malware.$0.02free to try
Package audit lockfileAudit a whole lockfile for known vulnerabilities and malware in one call: package-lock.json, yarn.lock, pnpm-lock.yaml, requirements.txt, poetry.lock, uv.lock, Pipfile.lock, Cargo.lock or go.sum, up to 1,000 exact versions checked against OSV.dev, with affected packages, severity and versions to upgrade to.$0.05
Dependency verdict"Should I use this dependency?" in one call for npm, PyPI, crates or Go: full package safety check (vulnerabilities, malware, typosquats, deprecation, licence, downloads) plus its GitHub repository health (activity, bus factor, releases, Scorecard), a clear decision (use / use-with-care / avoid) with reasons, and plain-English advice.$0.03free to try
CVEVulnerability lookup for agents: by id (?id=CVE-2021-44228, GHSA-..., PYSEC-..., RUSTSEC-..., GO-...) get the advisory, severity/CVSS, affected packages and fixed versions, exploit probability (EPSS) and whether CISA lists it as exploited in the wild; or by package (?ecosystem=npm&package=lodash[&version=]) list every advisory with the same enrichment.$0.003free to try
GitHub actionIs this GitHub Action safe for your workflow?$0.005free to try

Questions people ask

Where does the vulnerability data come from?

OSV.dev, the open vulnerability database that includes GitHub security advisories, PyPA, RustSec and the Go vulnerability database, plus FIRST's EPSS scores and CISA's list of known exploited vulnerabilities.

Which ecosystems are covered?

npm, PyPI, crates.io and Go modules. The lockfile audit reads the common lockfiles for each.

Does it replace npm audit or Dependabot?

It uses much of the same advisory data, but it's built for an AI assistant to call before it adds a package, and it also checks for typosquats, deprecation and install scripts.

How much does it cost?

From $0.003 a call, charged only when the check succeeds. In Claude or Cursor the first 20 calls a day are free, with no sign-up.

More: every use case · developer docs · llms.txt